mediawiki/core Security Advisories for 1.33.2 (5)
-
[HIGH] MediaWiki Denial of Service vulnerability
PKSA-wzph-c8jf-dsw9 CVE-2023-45363 GHSA-w5fx-cx7f-6vr9
Affected version: =1.40.0|>=1.36.0,<1.39.5|<1.35.12
Reported by:
GitHub -
[CRITICAL] X-Forwarded-For header allows brute-forcing autoblocked IP addresses
PKSA-sywz-vkhh-67ff CVE-2023-29141 GHSA-5vj8-g3qg-4qh6
Affected version: <1.35.10|>=1.38.0,<1.38.6|>=1.39.0,<1.39.3
Reported by:
GitHub -
[MEDIUM] MediaWiki allows a denial of service
PKSA-qcmj-k84v-rjky CVE-2021-41800 GHSA-c8wv-qwwc-6j73
Affected version: <1.36.2
Reported by:
GitHub -
[MEDIUM] img_auth.php may leak private extension images into the public cache
PKSA-ddy8-wbbj-hqfh CVE-2020-15005 GHSA-xpv7-93cm-4mxv
Affected version: >=1.34.0,<1.34.2|>=1.32.0,<1.33.4|<1.31.8
Reported by:
GitHub -
[MEDIUM] makeCollapsible allows applying event handler to any CSS selector
PKSA-pvds-fsx9-62mq CVE-2020-10960 GHSA-pfm2-mqwj-ggm5
Affected version: >=1.31.0,<1.31.7|>=1.33.0,<1.33.3|>=1.34.0,<1.34.1
Reported by:
GitHub, FriendsOfPHP/security-advisories